Enabling remote access without exposing control systems

Remote access is essential in Battery Energy Storage Systems. Good OT cybersecurity for BESS is about deliberate access, clear segmentation, and predictable behaviour – not bolting on controls after the fact.

OEMs need visibility. Engineers need to diagnose issues. Operators need confidence that access is controlled and auditable.

The risk isn’t remote access itself – the risk is granting access without clear boundaries, visibility, or intent.

1. Where remote access and security break down

Most OT security issues in BESS environments don’t start with malicious intent. They start with convenience.

Common problems include:

  • flat networks where IT, monitoring, and control traffic coexist
  • shared credentials and permanent VPN access for vendors
  • limited visibility into what devices and protocols are active
  • security controls added late, after commissioning pressure
  • assumptions that “air-gapped” still means isolated

BESS environments are inherently multi-vendor. Different OEMs, integrators, and support teams all need access at different times, and for different reasons.

Without clear segmentation and access control, remote connectivity becomes an open door rather than a managed hand-off.

2. What effective OT security looks like in BESS networks

Strong OT cybersecurity doesn’t require complexity. It requires clarity.

Effective BESS security designs share a few core principles:

  • Clear IT/OT separation
    Control and protection systems are isolated from corporate and monitoring traffic.
  • Intentional segmentation
    VLANs, firewall rules, and access controls define exactly what can talk to what.
  • Visibility before restriction
    Operators understand what devices and protocols are present before locking things down.
  • Scoped remote access
    Vendors and OEMs access only the systems required, for a defined period.
  • Auditability
    Every remote session can be traced – who accessed what, and when.

Approaches such as Zero Trust Network Access (ZTNA) support this model by granting access to specific devices or services rather than entire networks. Access is deliberate, monitored, and revoked when no longer required.

The objective is to make access predictable, observable, and reversible.

3. How Madison approaches remote access and OT cybersecurity

Our approach to OT security starts with network design, not security tools.

In practice, that means:

  • designing segmentation into the architecture from the outset
  • validating access paths and trust boundaries before commissioning
  • ensuring visibility into devices, protocols, and traffic patterns
  • aligning security controls with operational requirements
  • supporting controlled remote access without exposing control systems

Platforms from vendors such as Cisco and Moxa are widely used in BESS environments because they support segmented architectures, secure management, and long-term support aligned with IEC 62443 principles. When combined with disciplined design and validation, they allow secure access without compromising system stability.

Our focus is practical: security that supports operations instead of getting in the way.

Design secure access before it becomes urgent

OT security decisions made under pressure are rarely good ones.

Our BESS Connectivity FAQ covers the real-world segmentation, visibility, and remote access questions that consistently arise on storage and microgrid projects — based on how these networks are deployed and supported in the field.

It’s a practical reference for teams who want secure access without unintended exposure.

This field is for validation purposes and should be left unchanged.

Same day dispatch on all stocked items.